Edition of June 9, 2026, continued — page 2 of 2. Back to page 1
| CVE | CVSS | EPSS %ile | Vendor | Product | CWE | Title |
|---|---|---|---|---|---|---|
| CVE-2026-46373 | 7.5 | 18.2 | sqlfluff | sqlfluff | CWE-674 | SQLFluff: Recursive Stack Overflow in Parser |
| CVE-2026-46374 | 7.5 | 18.2 | sqlfluff | sqlfluff | CWE-400 | SQLFluff: Uncontrolled Resource Consumption in Parser |
| CVE-2026-44818 | 7.0 | 18.3 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-362 | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2017-20243 | 8.8 | 18.0 | QuanticaLabs | Car Park Booking System | CWE-89 | WordPress Car Park Booking Plugin SQL Injection via space_id |
| CVE-2017-20247 | 8.8 | 18.0 | Apptha | PICA Photo Gallery | CWE-89 | WordPress Plugin PICA Photo Gallery 1.0 SQL Injection |
| CVE-2026-41696 | 5.9 | 18.1 | Spring | Spring Data MongoDB | CWE-943 | Spring Data MongoDB Bind Parameter Literal Quoting Breakout |
| CVE-2026-48289 | 3.5 | 18.1 | Adobe | Adobe Experience Manager | CWE-20 | Adobe Experience Manager | Improper Input Validation (CWE-20) |
| CVE-2026-44810 | 7.8 | 18.0 | Microsoft | Windows 11 version 23H2 | CWE-287 | Microsoft Cryptographic Services Elevation of Privilege Vulnerability |
| CVE-2026-47946 | 5.4 | 17.8 | Adobe | Adobe Experience Manager | CWE-79 | Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79) |
| CVE-2026-47947 | 5.4 | 17.8 | Adobe | Adobe Experience Manager | CWE-79 | Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79) |
| CVE-2026-48258 | 5.4 | 17.8 | Adobe | Adobe Experience Manager | CWE-79 | Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79) |
| CVE-2026-48265 | 5.4 | 17.8 | Adobe | Adobe Experience Manager | CWE-79 | Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79) |
| CVE-2026-48266 | 5.4 | 17.8 | Adobe | Adobe Experience Manager | CWE-79 | Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79) |
| CVE-2026-48271 | 5.4 | 17.8 | Adobe | Adobe Experience Manager | CWE-79 | Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79) |
| CVE-2026-48280 | 5.4 | 17.8 | Adobe | Adobe Experience Manager | CWE-79 | Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79) |
| CVE-2026-46540 | 6.5 | 17.7 | nimiq | core-rs-albatross | CWE-841 | Nimiq light-blockchain: Light blockchain rebranch issue |
| CVE-2026-11792 | 3.3 | 17.7 | Red Hat | Red Hat Directory Server 11 | CWE-122 | 389-ds-base: 389-ds-base: heap buffer overflow in audit log password masking … |
| CVE-2026-50512 | 7.8 | 17.6 | Microsoft | Microsoft PC Manager | CWE-306 | Microsoft PC Manager Elevation of Privilege Vulnerability |
| CVE-2026-41720 | 7.4 | 17.5 | Spring | Spring LDAP | CWE-287 | Authentication Bypass with Empty Password in Spring LDAP |
| CVE-2026-5714 | 6.4 | 17.5 | shortpixel | Enable Media Replace | CWE-79 | Enable Media Replace <= 4.1.8 - Authenticated (Author+) Stored Cross-Site Scr… |
| CVE-2026-0409 | 4.8 | 17.4 | NETGEAR | Orbi 370 | CWE-119 | Netgear Orbi 370 Series Remote Code Execution vulnerability |
| CVE-2026-47346 | 7.6 | 16.9 | TYPO3 | TYPO3 CMS | CWE-178 | TYPO3 CMS - Broken Access Control in Form Framework |
| CVE-2026-10738 | 6.4 | 17.0 | weaverlancegmailcom | jQuery Hover Footnotes | CWE-79 | jQuery Hover Footnotes <= 1.4 - Authenticated (Author+) Stored Cross-Site Scr… |
| CVE-2026-7542 | 6.5 | 16.8 | Revolution Slider | Slider Revolution | CWE-200 | Slider Revolution 7.0 - 7.0.10 - Authenticated (Subscriber+) Sensitive Inform… |
| CVE-2026-42984 | 7.0 | 16.7 | Microsoft | Windows 10 Version 1809 | CWE-416 | Windows Kernel Elevation of Privilege Vulnerability |
| CVE-2026-45653 | 7.0 | 16.7 | Microsoft | Windows 10 Version 1607 | CWE-416 | Windows Kernel Elevation of Privilege Vulnerability |
| CVE-2026-36720 | 8.1 | 16.3 | n/a | n/a | CWE-284 | Insecure permissions in bookcars v8.3 allows authenticated attackers to escal… |
| CVE-2026-41840 | 5.9 | 16.3 | Spring | Spring Framework | CWE-401 | Spring WebFlux applications are vulnerable to Denial of Service (DoS) attacks… |
| CVE-2026-42978 | 7.8 | 16.1 | Microsoft | Windows 10 Version 1809 | CWE-362 | Windows Push Notifications Elevation of Privilege Vulnerability |
| CVE-2026-0418 | 4.3 | 15.9 | NETGEAR | CBR750 | CWE-610 | Certain NETGEAR devices allow administrators to tamper with system |
| CVE-2026-49741 | 8.7 | 15.8 | TYPO3 | TYPO3 CMS | CWE-89 | TYPO3 CMS - Privilege Escalation & SQL Injection in Form Framework |
| CVE-2026-8677 | 6.4 | 15.7 | wpmessiah | Prime Elementor Addons – Lightweight Elementor Widgets for Faster Pages | CWE-79 | Prime Elementor Addons <= 1.3.3 - Authenticated (Contributor+) Stored Cross-S… |
| CVE-2026-41031 | 9.3 | 15.6 | Skilja GmbH | Vinna Process Monitor | CWE-79 | A Stored Cross-Site Scripting (XSS) vulnerability occurs in Vinna Process Mon… |
| CVE-2026-47931 | 8.4 | 15.6 | Adobe | ColdFusion | CWE-20 | ColdFusion | Improper Input Validation (CWE-20) |
| CVE-2026-46747 | 5.3 | 15.6 | Siemens | SINEC INS | CWE-26 | A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Upd… |
| CVE-2026-7556 | 7.2 | 15.5 | foliovision | FV Flowplayer Video Player | CWE-79 | FV Flowplayer Video Player <= 7.5.49.7212 - Unauthenticated Stored Cross-Site… |
| CVE-2026-41727 | 6.5 | 15.3 | Spring | Spring for Apache Kafka | CWE-20 | In Spring for Apache Kafka, forged retry topic headers subvert retry routing … |
| CVE-2026-49161 | 7.8 | 15.1 | Microsoft | Microsoft PC Manager | CWE-284 | Microsoft PC Manager Security Feature Bypass Vulnerability |
| CVE-2026-11607 | 7.6 | 15.1 | TYPO3 | TYPO3 CMS | CWE-862 | TYPO3 CMS - Broken Access Control in Form Framework |
| CVE-2026-47343 | 7.2 | 15.1 | TYPO3 | TYPO3 CMS | CWE-862 | TYPO3 CMS - Destructive Actions on File Mount Folders |
| CVE-2026-47349 | 5.3 | 15.1 | TYPO3 | TYPO3 CMS | CWE-862 | TYPO3 CMS - Broken Access Control in Recycler |
| CVE-2026-47350 | 5.3 | 15.1 | TYPO3 | TYPO3 CMS | CWE-862 | TYPO3 CMS - Broken Access Control in DataHandler |
| CVE-2026-47351 | 5.3 | 15.1 | TYPO3 | TYPO3 CMS | CWE-200 | TYPO3 CMS - Broken Access Control in Clipboard |
| CVE-2026-47352 | 5.3 | 15.1 | TYPO3 | TYPO3 CMS | CWE-862 | TYPO3 CMS - Broken Access Control in Backend API |
| CVE-2026-34181 | 7.4 | 14.7 | OpenSSL | OpenSSL | CWE-354 | PKCS#12 Files with PBMAC1 Are Accepted with Short HMAC Keys |
| CVE-2026-46320 | 7.4 | 14.7 | Linux | Linux | — | tap: free page on error paths in tap_get_user_xdp() |
| CVE-2026-9211 | 5.2 | 14.6 | NETGEAR | CAX30 | CWE-20 | Certain NETGEAR routers allow unauthenticated users to gain control of the ro… |
| CVE-2026-34335 | 7.0 | 14.5 | Microsoft | Windows 10 Version 1607 | CWE-416 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerab… |
| CVE-2026-42911 | 7.0 | 14.5 | Microsoft | Windows 10 Version 1607 | CWE-416 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerab… |
| CVE-2026-45640 | 7.0 | 14.5 | Microsoft | Windows 10 Version 21H2 | CWE-416 | Windows Bluetooth Port Driver Elevation of Privilege Vulnerability |
| CVE-2026-47293 | 7.0 | 14.5 | Microsoft | Microsoft 365 Apps for Enterprise | CWE-416 | Microsoft Office Click-To-Run Elevation of Privilege Vulnerability |
| CVE-2026-8599 | 6.4 | 14.5 | mailerpress | MailerPress – Email Marketing, Newsletter, Email Automation & WooCommerce Emails | CWE-79 | MailerPress <= 2.0.4 - Authenticated (Author+) Stored Cross-Site Scripting vi… |
| CVE-2026-8045 | 7.1 | 14.4 | Schneider Electric | EcoStruxure™ IT Data Center Expert | CWE-611 | CWE-611 Improper Restriction of XML External Entity Reference vulnerability e… |
| CVE-2026-39169 | 7.5 | 14.3 | n/a | n/a | CWE-284 | SEMCMS 5.0 is vulnerable to unauthorized access in SEMCMS_copy.php. |
| CVE-2026-46492 | 6.1 | 14.3 | commenthol | md-fileserver | CWE-80 | md-fileserver: Stored/Reflected XSS when viewing Markdown (raw HTML allowed) |
| CVE-2026-44748 | 9.9 | 14.2 | SAP_SE | SAP NetWeaver AS ABAP and ABAP Platform | CWE-347 | XML Signature Wrapping in SAML Authentication in SAP NetWeaver AS ABAP and AB… |
| CVE-2026-46542 | 4.3 | 14.2 | nimiq | core-rs-albatross | CWE-617 | nimiq-keys: Denial of service in Ed25519 multisig delinearization via invalid… |
| CVE-2026-47991 | 6.1 | 14.1 | Adobe | Adobe Experience Manager | CWE-601 | Adobe Experience Manager | URL Redirection to Untrusted Site ('Open Redirect'… |
| CVE-2026-0415 | 4.3 | 14.0 | NETGEAR | RBE970 | CWE-20 | Insufficient input validation vulnerability in certain Orbi routers |
| CVE-2026-0417 | 4.3 | 14.0 | NETGEAR | MR60 | CWE-20 | Insufficient input validation in certain NETGEAR routers |
| CVE-2026-11764 | 3.6 | 13.9 | pretix | pretix | CWE-280 | Data exposed without proper permission |
| CVE-2026-10024 | 6.4 | 13.8 | 360crest | TinyMCE shortcode Addon | CWE-79 | TinyMCE shortcode Addon <= 1.0.0 - Authenticated (Contributor+) Stored Cross-… |
| CVE-2026-53675 | 5.3 | 13.6 | BuddyPress | BuddyPress | CWE-639 | BuddyPress 14.4.0 Friends List IDOR via REST API |
| CVE-2026-41697 | 4.8 | 13.7 | Spring | Spring Data Relational | CWE-943 | Spring Data Relational Parameter not Escaped for Query By Example LIKE Pattern |
| CVE-2026-46433 | 6.5 | 13.5 | lldpd | lldpd | CWE-125 | lldpd: Heap OOB Read in VLAN Decapsulation memmove |
| CVE-2026-9754 | 7.1 | 13.3 | MongoDB | MongoDB | CWE-457 | Stack memory disclosure in filemd5 command |
| CVE-2026-44744 | 6.5 | 13.2 | SAP_SE | SAP S/4HANA | CWE-89 | SQL Injection vulnerability in SAP S/4HANA |
| CVE-2026-40991 | 5.9 | 13.1 | Spring | Spring REST Docs | CWE-611 | XML External Entity (XXE) injection when documenting untrusted XML content |
| CVE-2026-49472 | 5.3 | 13.2 | signalwire | freeswitch | CWE-116 | FreeSWITCH includes a vulnerable function, PREFIX(prologTok)() from libexpat |
| CVE-2016-20063 | 7.1 | 12.9 | Md. Shamim Shahnewaz | Single Personal Message | CWE-89 | Single Personal Message 1.0.3 WordPress Plugin SQL Injection |
| CVE-2026-32856 | 5.1 | 12.8 | Ellucian | Banner Self-Service | CWE-79 | Ellucian Banner Self-Service Reflected XSS via dateConverter |
| CVE-2026-44754 | 6.6 | 12.6 | SAP_SE | ODP Data Replication APIs | CWE-862 | Missing caller identification check-in for ODP Data Replication APIs |
| CVE-2026-0410 | 1.9 | 12.6 | NETGEAR | R7000 | CWE-20 | Insufficient input validation in certain NETGEAR routers |
| CVE-2026-47648 | 7.0 | 12.6 | Microsoft | Windows 10 Version 1607 | CWE-426 | Windows Storage Elevation of Privilege Vulnerability |
| CVE-2026-42771 | 6.2 | 12.5 | OpenSSL | OpenSSL | CWE-125 | Possible Out of Bounds Read in X509_VERIFY_PARAM_set1_email() |
| CVE-2026-11621 | 2.0 | 12.5 | n/a | Dcat-Admin | CWE-284 | Dcat-Admin User Setting upload editorMDUpload unrestricted upload |
| CVE-2023-43688 | 7.5 | 12.4 | n/a | n/a | CWE-122 | An issue was discovered in Malwarebytes 4.x and 5.x (and Nebula 2020-10-21 an… |
| CVE-2026-36777 | 6.5 | 12.4 | n/a | n/a | CWE-121 | Shenzhen Tenda Technology Co., Ltd Tenda W3 Wireless Router v1.0.0.3(2204) wa… |
| CVE-2026-36722 | 5.4 | 12.4 | n/a | n/a | CWE-434 | An authenticated arbitrary file upload vulnerability in the /api/create-car-i… |
| CVE-2026-11799 | 7.5 | 12.2 | Mozilla | Focus for iOS | CWE-79 | UXSS in Focus for iOS / Klar Webkit navigation |
| CVE-2026-9210 | 4.9 | 12.2 | NETGEAR | EX3700 | CWE-20 | Certain NETGEAR routers allow authenticated administrators to gain unintended… |
| CVE-2026-45647 | 7.0 | 12.2 | Microsoft | Microsoft Defender for Endpoint for Mac | CWE-367 | Microsoft Defender for Endpoint for Mac Elevation of Privilege Vulnerability |
| CVE-2026-49740 | 6.3 | 12.2 | TYPO3 | TYPO3 CMS | CWE-502 | TYPO3 CMS - Insecure Deserialization in Core API |
| CVE-2026-41706 | 6.1 | 11.6 | Spring | Spring Security | CWE-601 | Open Redirect When Using CookieRequestCache |
| CVE-2026-28301 | 4.8 | 11.5 | SolarWinds | Observability Self-Hosted | CWE-601 | SolarWinds Observability Self-Hosted Open Redirect Vulnerability |
| CVE-2026-10045 | 9.8 | 11.3 | Shenzhen Kangda Xin Intelligent Network Technology Co., Ltd | DR300 | — | CVE-2026-10045 |
| CVE-2026-47916 | 7.8 | 11.3 | Adobe | Acrobat Reader | CWE-416 | Acrobat Reader | Use After Free (CWE-416) |
| CVE-2026-11619 | 2.1 | 11.4 | Dolibarr | ERP CRM | CWE-266 | Dolibarr ERP CRM Legacy Filemanager config.inc.php improper authorization |
| CVE-2026-46518 | 8.7 | 11.2 | openemr | openemr | CWE-79 | OpenEMR: Stored XSS in prescription CSS/HTML print view via patient demographics |
| CVE-2026-44751 | 7.1 | 11.0 | SAP_SE | SAP NetWeaver AS ABAP and ABAP Platform | CWE-862 | Missing Authorization check in Application Server ABAP of SAP NetWeaver and A… |
| CVE-2026-46748 | 8.7 | 10.9 | Siemens | SINEC INS | CWE-250 | A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Upd… |
| CVE-2026-41719 | 6.4 | 11.0 | Spring | Spring Data KeyValue | CWE-917 | Spring Data KeyValue - SpEL Injection vulnerability in SpelPropertyComparator |
| CVE-2026-42912 | 7.0 | 10.9 | Microsoft | Windows 10 Version 1607 | CWE-362 | Windows Telephony Service Elevation of Privilege Vulnerability |
| CVE-2026-11603 | 6.1 | 10.8 | brthumar1959 | Product Filter Widget for Elementor | CWE-79 | Product Filter Widget for Elementor <= 1.0.6 - Reflected Cross-Site Scripting… |
| CVE-2026-47936 | 5.4 | 10.9 | Adobe | Adobe Experience Manager | CWE-79 | Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79) |
| CVE-2026-47944 | 5.4 | 10.9 | Adobe | Adobe Experience Manager | CWE-79 | Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79) |
| CVE-2026-47949 | 5.4 | 10.9 | Adobe | Adobe Experience Manager | CWE-79 | Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79) |
| CVE-2026-47950 | 5.4 | 10.9 | Adobe | Adobe Experience Manager | CWE-79 | Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79) |
| CVE-2026-47951 | 5.4 | 10.9 | Adobe | Adobe Experience Manager | CWE-79 | Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79) |
| CVE-2026-47953 | 5.4 | 10.9 | Adobe | Adobe Experience Manager | CWE-79 | Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79) |
| CVE-2026-47954 | 5.4 | 10.9 | Adobe | Adobe Experience Manager | CWE-79 | Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79) |
| CVE-2026-47956 | 5.4 | 10.9 | Adobe | Adobe Experience Manager | CWE-79 | Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79) |
| CVE-2026-47957 | 5.4 | 10.9 | Adobe | Adobe Experience Manager | CWE-79 | Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79) |
| CVE-2026-47958 | 5.4 | 10.9 | Adobe | Adobe Experience Manager | CWE-79 | Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79) |
| CVE-2026-47962 | 5.4 | 10.9 | Adobe | Adobe Experience Manager | CWE-79 | Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79) |
| CVE-2026-47966 | 5.4 | 10.9 | Adobe | Adobe Experience Manager | CWE-79 | Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79) |
| CVE-2026-47972 | 5.4 | 10.9 | Adobe | Adobe Experience Manager | CWE-79 | Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79) |
| CVE-2026-47973 | 5.4 | 10.9 | Adobe | Adobe Experience Manager | CWE-79 | Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79) |
| CVE-2026-47974 | 5.4 | 10.9 | Adobe | Adobe Experience Manager | CWE-79 | Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79) |
| CVE-2026-47975 | 5.4 | 10.9 | Adobe | Adobe Experience Manager | CWE-79 | Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79) |
| CVE-2026-47977 | 5.4 | 10.9 | Adobe | Adobe Experience Manager | CWE-79 | Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79) |
| CVE-2026-47978 | 5.4 | 10.9 | Adobe | Adobe Experience Manager | CWE-79 | Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79) |
| CVE-2026-47980 | 5.4 | 10.9 | Adobe | Adobe Experience Manager | CWE-79 | Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79) |
| CVE-2026-47981 | 5.4 | 10.9 | Adobe | Adobe Experience Manager | CWE-79 | Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79) |
| CVE-2026-47990 | 5.4 | 10.9 | Adobe | Adobe Experience Manager | CWE-79 | Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79) |
| CVE-2026-48297 | 5.4 | 10.9 | Adobe | Adobe Experience Manager | CWE-79 | Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79) |
| CVE-2026-48299 | 5.4 | 10.9 | Adobe | Adobe Experience Manager | CWE-79 | Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79) |
| CVE-2026-48300 | 5.4 | 10.9 | Adobe | Adobe Experience Manager | CWE-79 | Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79) |
| CVE-2026-48301 | 5.4 | 10.9 | Adobe | Adobe Experience Manager | CWE-79 | Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79) |
| CVE-2026-48304 | 5.4 | 10.9 | Adobe | Adobe Experience Manager | CWE-79 | Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79) |
| CVE-2026-47933 | 4.8 | 10.8 | Adobe | ColdFusion | CWE-79 | ColdFusion | Cross-site Scripting (Stored XSS) (CWE-79) |
| CVE-2026-41003 | 5.4 | 10.6 | Spring | Spring Security | CWE-79 | Unencoded HTML Outputs in Spring Security May Allow Cross-Site Scripting |
| CVE-2026-49938 | 6.5 | 10.3 | Fortinet | FortiPortal | CWE-284 | A improper access control vulnerability in Fortinet FortiPortal 7.4.0 through… |
| CVE-2026-44746 | 6.1 | 10.0 | SAP_SE | SAP NetWeaver AS Java (JDBC Test Servlet) | CWE-79 | Reflected Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver AS Java (… |
| CVE-2026-34416 | 5.1 | 10.0 | brian-ruf | OSCAL-GUI | CWE-79 | OSCAL-GUI Reflected XSS via project parameter in oscal.php |
| CVE-2026-40993 | 7.2 | 9.9 | Spring | Spring Security | CWE-502 | Unfiltered Java Native Deserialization of SAML 2.0 Asserting Party Credential… |
| CVE-2026-42836 | 7.0 | 9.9 | Microsoft | Windows 10 Version 1607 | CWE-362 | Windows Function Discovery Service (fdwsd.dll) Elevation of Privilege Vulnera… |
| CVE-2026-4986 | 5.3 | 9.9 | Unknown | WPForms | CWE-862 | WPForms Lite < 1.10.0.5 – Unauthenticated PayPal Webhook Forgery |
| CVE-2026-41730 | 5.3 | 9.8 | Spring | Spring Data REST | CWE-209 | Spring Data REST exposes persistence-layer internals in error responses |
| CVE-2026-41839 | 4.2 | 9.7 | Spring | Spring Framework | CWE-384 | Spring Framework Escalation via Session Fixation in WebFlux |
| CVE-2026-47106 | 5.1 | 9.7 | Ellucian | Banner Self-Service | CWE-79 | Ellucian Banner Self-Service Stored XSS via getFacultyMeetingTimes API |
| CVE-2026-46332 | 8.0 | 9.3 | Linux | Linux | CWE-120 | greybus: gb-beagleplay: bound bootloader receive buffering |
| CVE-2026-41539 | 6.3 | 9.3 | QNAP Systems Inc. | QTS | CWE-79 | QTS, QuTS hero |
| CVE-2026-7662 | 6.4 | 9.2 | joshin85 | Plugin Name: ePaperFlip Publisher | CWE-79 | ePaperFlip Publisher <= 1 - Authenticated (Contributor+) Stored Cross-Site Sc… |
| CVE-2026-8880 | 6.4 | 9.2 | romancartsupport | RomanCart Ecommerce | CWE-79 | RomanCart Ecommerce <= 2.0.8 - Authenticated (Contributor+) Stored Cross-Site… |
| CVE-2025-55651 | 5.5 | 9.2 | n/a | n/a | CWE-476 | A NULL pointer dereference in the gf_isom_get_user_data_count function (isome… |
| CVE-2026-40639 | 5.7 | 9.1 | Dell | Dell Edge Gateway 3000 | CWE-261 | Dell Client Platform BIOS contains a Weak Encoding for Password vulnerability… |
| CVE-2026-41837 | 5.3 | 9.1 | Spring | Spring Data REST | CWE-284 | Spring Data REST Querydsl integration exposes Jackson-hidden persistent field… |
| CVE-2026-34692 | 5.4 | 8.9 | Adobe | Adobe Experience Manager | CWE-79 | Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79) |
| CVE-2026-47935 | 5.4 | 8.9 | Adobe | Adobe Experience Manager | CWE-79 | Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79) |
| CVE-2026-47982 | 5.4 | 8.9 | Adobe | Adobe Experience Manager | CWE-79 | Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79) |
| CVE-2026-47983 | 5.4 | 8.9 | Adobe | Adobe Experience Manager | CWE-79 | Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79) |
| CVE-2026-47985 | 5.4 | 8.9 | Adobe | Adobe Experience Manager | CWE-79 | Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79) |
| CVE-2026-47986 | 5.4 | 8.9 | Adobe | Adobe Experience Manager | CWE-79 | Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79) |
| CVE-2026-47987 | 5.4 | 8.9 | Adobe | Adobe Experience Manager | CWE-79 | Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79) |
| CVE-2026-47989 | 5.4 | 8.9 | Adobe | Adobe Experience Manager | CWE-79 | Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79) |
| CVE-2026-47993 | 5.4 | 8.9 | Adobe | Adobe Experience Manager | CWE-79 | Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79) |
| CVE-2026-48250 | 5.4 | 8.9 | Adobe | Adobe Experience Manager | CWE-79 | Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79) |
| CVE-2026-48251 | 5.4 | 8.9 | Adobe | Adobe Experience Manager | CWE-79 | Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79) |
| CVE-2026-48256 | 5.4 | 8.9 | Adobe | Adobe Experience Manager | CWE-79 | Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79) |
| CVE-2026-48264 | 5.4 | 8.9 | Adobe | Adobe Experience Manager | CWE-79 | Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79) |
| CVE-2026-48268 | 5.4 | 8.9 | Adobe | Adobe Experience Manager | CWE-79 | Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79) |
| CVE-2026-8883 | 6.4 | 8.7 | helpstring | Global Body Mass Index Calculator | CWE-79 | Global Body Mass Index Calculator <= 1.2 - Authenticated (Contributor+) Store… |
| CVE-2026-8977 | 6.4 | 8.7 | techjewel | WP GDPR Cookie Consent | CWE-79 | WP GDPR Cookie Consent <= 1.0.0 - Authenticated (Subscriber+) Stored Cross-Si… |
| CVE-2026-44743 | 3.7 | 8.8 | SAP_SE | SAP Business Objects | CWE-497 | Security Misconfiguration vulnerability in SAP Business Objects |
| CVE-2026-25557 | 5.1 | 8.7 | Evoluted | PHP Directory Listing Script | CWE-79 | Evoluted PHP Directory Listing Script 4.0.5 Reflected XSS via dir parameter |
| CVE-2026-45597 | 7.0 | 8.5 | Microsoft | Windows 11 version 23H2 | CWE-362 | Windows UI Automation Manager (uiamanager.dll) Elevation of Privilege Vulnera… |
| CVE-2025-40808 | 6.9 | 8.5 | Siemens | SIPROTEC 5 6MD84 (CP300) | CWE-434 | A vulnerability has been identified in SIPROTEC 5 6MD84 (CP300) (All versions… |
| CVE-2026-41853 | 5.3 | 8.5 | Spring | Spring Framework | CWE-444 | Spring Framework Multipart Request Smuggling in Spring MVC and WebFlux |
| CVE-2026-42977 | 7.8 | 8.4 | Microsoft | Windows 10 Version 1809 | CWE-362 | Windows Push Notifications Elevation of Privilege Vulnerability |
| CVE-2026-42979 | 7.8 | 8.4 | Microsoft | Windows 10 Version 1809 | CWE-362 | Windows Push Notifications Elevation of Privilege Vulnerability |
| CVE-2026-47926 | 5.5 | 8.4 | Adobe | Acrobat Reader | CWE-125 | Acrobat Reader | Out-of-bounds Read (CWE-125) |
| CVE-2026-45487 | 7.0 | 8.3 | Microsoft | Windows 10 Version 21H2 | CWE-367 | Windows Program Compatibility Assistant Service Elevation of Privilege Vulner… |
| CVE-2026-8841 | 6.4 | 8.0 | andrewabarber | Extra Settings for RocketChat | CWE-79 | Extra Settings for RocketChat <= 0.1 - Authenticated (Contributor+) Stored Cr… |
| CVE-2026-8882 | 6.4 | 8.0 | jdm-labs | WP ApplicantStack Jobs Display | CWE-79 | WP ApplicantStack Jobs Display <= 1.1.1 - Authenticated (Contributor+) Stored… |
| CVE-2026-8895 | 6.4 | 8.0 | kenz60 | kk blog card | CWE-79 | kk blog card <= 1.3 - Authenticated (Contributor+) Stored Cross-Site Scriptin… |
| CVE-2026-36725 | 6.1 | 8.0 | n/a | n/a | CWE-79 | A markdown based cross-site scripting (XSS) vulnerability in the /system/noti… |
| CVE-2026-36772 | 6.5 | 7.8 | n/a | n/a | CWE-121 | Shenzhen Tenda Technology Co., Ltd Tenda W3 Wireless Router v1.0.0.3(2204) wa… |
| CVE-2026-36773 | 6.5 | 7.8 | n/a | n/a | CWE-121 | Shenzhen Tenda Technology Co., Ltd Tenda W3 Wireless Router v1.0.0.3(2204) wa… |
| CVE-2026-0416 | 4.3 | 7.8 | NETGEAR | RAXE450 | CWE-20 | Improper input validation in certain NETGEAR routers allows unauthorized modi… |
| CVE-2026-45596 | 7.0 | 7.7 | Microsoft | Windows 10 Version 1607 | CWE-362 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerab… |
| CVE-2026-45598 | 7.0 | 7.7 | Microsoft | Windows 10 Version 1607 | CWE-362 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerab… |
| CVE-2026-45601 | 7.0 | 7.7 | Microsoft | Windows 10 Version 1607 | CWE-362 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerab… |
| CVE-2026-45603 | 7.0 | 7.7 | Microsoft | Windows 10 Version 1607 | CWE-416 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerab… |
| CVE-2026-11785 | 4.3 | 7.8 | Red Hat | Red Hat Directory Server 11 | CWE-843 | 389-ds-base: 389-ds-base: partial stack address information leak via ber_prin… |
| CVE-2026-34707 | 7.8 | 7.6 | Adobe | InCopy | CWE-122 | InCopy | Heap-based Buffer Overflow (CWE-122) |
| CVE-2026-34657 | 5.5 | 7.6 | Adobe | CAI Content Credentials | CWE-22 | CAI Content Credentials | Improper Limitation of a Pathname to a Restricted D… |
| CVE-2026-47906 | 8.6 | 7.5 | Adobe | Dreamweaver Desktop | CWE-1395 | Dreamweaver Desktop | Dependency on Vulnerable Third-Party Component (CWE-1395) |
| CVE-2026-11787 | 6.3 | 7.5 | Red Hat | Red Hat Directory Server 11 | CWE-126 | 389-ds-base: 389-ds-base: heap buffer over-read in ldap_utf8prev() via str2si… |
| CVE-2026-41852 | 5.3 | 7.6 | Spring | Spring Framework | CWE-863 | Spring Framework Arbitrary Method Invocation in SpEL Expressions |
| CVE-2026-11822 | 8.5 | 7.3 | SQLite | SQLite | CWE-122 | SQLite before 3.53.2 Memory Corruption in FTS5 Extension |
| CVE-2026-11824 | 8.5 | 7.3 | SQLite | SQLite | CWE-122 | SQLite before 3.53.2 Heap Buffer Overflow via FTS5 fts5ChunkIterate |
| CVE-2026-34695 | 7.8 | 7.2 | Adobe | InDesign Desktop | CWE-121 | InDesign Desktop | Stack-based Buffer Overflow (CWE-121) |
| CVE-2026-34697 | 7.8 | 7.2 | Adobe | InDesign Desktop | CWE-121 | InDesign Desktop | Stack-based Buffer Overflow (CWE-121) |
| CVE-2026-34698 | 7.8 | 7.2 | Adobe | InDesign Desktop | CWE-122 | InDesign Desktop | Heap-based Buffer Overflow (CWE-122) |
| CVE-2026-34699 | 7.8 | 7.2 | Adobe | InDesign Desktop | CWE-122 | InDesign Desktop | Heap-based Buffer Overflow (CWE-122) |
| CVE-2026-34701 | 7.8 | 7.2 | Adobe | InDesign Desktop | CWE-122 | InDesign Desktop | Heap-based Buffer Overflow (CWE-122) |
| CVE-2026-34702 | 7.8 | 7.2 | Adobe | InDesign Desktop | CWE-121 | InDesign Desktop | Stack-based Buffer Overflow (CWE-121) |
| CVE-2026-34708 | 7.8 | 7.2 | Adobe | InCopy | CWE-121 | InCopy | Stack-based Buffer Overflow (CWE-121) |
| CVE-2026-34694 | 4.8 | 7.3 | Adobe | Adobe Experience Manager Forms JEE | CWE-79 | Adobe Experience Manager Forms JEE | Cross-site Scripting (Stored XSS) (CWE-79) |
| CVE-2026-47952 | 7.8 | 7.1 | Adobe | Acrobat Reader | CWE-122 | Acrobat Reader | Heap-based Buffer Overflow (CWE-122) |
| CVE-2026-47959 | 7.8 | 7.1 | Adobe | Acrobat Reader | CWE-121 | Acrobat Reader | Stack-based Buffer Overflow (CWE-121) |
| CVE-2026-24315 | 4.2 | 7.1 | SAP_SE | SAP Fiori (launchpad) | CWE-35 | Path Traversal Vulnerability in SAP Fiori (launchpad) |
| CVE-2026-42991 | 7.8 | 7.0 | Microsoft | Windows 10 Version 1809 | CWE-362 | Windows Push Notifications Elevation of Privilege Vulnerability |
| CVE-2026-41701 | 4.4 | 7.0 | Spring | Spring AMQP | CWE-330 | In Spring AMQP sequential correlation IDs enable reply poisoning on fixed rep… |
| CVE-2026-41008 | 6.1 | 6.9 | Spring | Spring Security | CWE-601 | Spring Security Authorization Server Open Redirect via request_uri |
| CVE-2026-41715 | 6.1 | 6.9 | Spring | Reactor Netty | CWE-522 | Reactor Netty HTTP Client Leaks Credentials On Protocol Downgrade Redirect |
| CVE-2026-49848 | 4.3 | 6.9 | signalwire | freeswitch | CWE-287 | FreeSWITCH: Pre-authentication `userVariables` injection in `mod_verto` |
| CVE-2026-41838 | 7.5 | 6.8 | Spring | Spring Framework | CWE-330 | Spring Framework Predictable Session ID in WebSocket Module |
| CVE-2026-47907 | 8.6 | 6.5 | Adobe | Dreamweaver Desktop | CWE-284 | Dreamweaver Desktop | Improper Access Control (CWE-284) |
| CVE-2026-47921 | 7.8 | 6.6 | Adobe | Acrobat Reader | CWE-416 | Acrobat Reader | Use After Free (CWE-416) |
| CVE-2026-34417 | 5.1 | 6.6 | brian-ruf | OSCAL-GUI | CWE-79 | OSCAL-GUI Reflected XSS via project parameter in oscal-forms.php |
| CVE-2026-42599 | 5.1 | 6.5 | sveltejs | svelte | CWE-79 | Cross-site scripting via spread attributes in Svelte SSR |
| CVE-2026-0414 | 4.3 | 6.5 | NETGEAR | RBE970 | CWE-94 | Insufficient Input Validation Allows Unauthorized Modification of Router Soft… |
| CVE-2026-34696 | 7.8 | 6.3 | Adobe | InDesign Desktop | CWE-416 | InDesign Desktop | Use After Free (CWE-416) |
| CVE-2026-47925 | 5.5 | 6.3 | Adobe | Acrobat Reader | CWE-190 | Acrobat Reader | Integer Overflow or Wraparound (CWE-190) |
| CVE-2026-41847 | 5.3 | 6.3 | Spring | Spring Framework | CWE-284 | Spring Framework Security Filter Bypass in WebFlux Kotlin Router DSL |
| CVE-2026-47920 | 7.8 | 6.2 | Adobe | Acrobat Reader | CWE-416 | Acrobat Reader | Use After Free (CWE-416) |
| CVE-2026-47955 | 7.8 | 6.2 | Adobe | Acrobat Reader | CWE-416 | Acrobat Reader | Use After Free (CWE-416) |
| CVE-2026-36728 | 5.4 | 5.9 | n/a | n/a | CWE-79 | A markdown based cross-site scripting (XSS) vulnerability in the AI assistant… |
| CVE-2026-47908 | 7.8 | 5.8 | Adobe | Dreamweaver Desktop | CWE-824 | Dreamweaver Desktop | Access of Uninitialized Pointer (CWE-824) |
| CVE-2026-41845 | 6.1 | 5.8 | Spring | Spring Framework | CWE-79 | Spring Framework Cross-site Scripting via JavaScriptUtils |
| CVE-2026-44750 | 4.3 | 5.8 | SAP_SE | SAP MDG (Review Match Groups Application) | CWE-862 | Missing Authorization check in SAP MDG (Review Match Groups Application) |
| CVE-2026-11786 | 6.5 | 5.7 | Red Hat | Red Hat Directory Server 11 | CWE-125 | 389-ds-base: 389-ds-base: heap out-of-bounds read in ldif parser str2entry_st… |
| CVE-2026-10862 | 6.4 | 5.1 | pickplugins | Accordions | CWE-79 | Accordions <= 2.3.23 - Authenticated (Custom+) Stored Cross-Site Scripting vi… |
| CVE-2026-34705 | 5.5 | 5.1 | Adobe | InDesign Desktop | CWE-125 | InDesign Desktop | Out-of-bounds Read (CWE-125) |
| CVE-2026-41972 | 5.4 | 5.1 | Huawei | HarmonyOS | CWE-22 | Path traversal vulnerability in the SMS app. Impact: Successful exploitation … |
| CVE-2026-24180 | 7.3 | 5.1 | NVIDIA | DALI | CWE-122 | NVIDIA DALI contains a vulnerability in a component where an attacker could c… |
| CVE-2026-47961 | 5.5 | 5.1 | Adobe | Acrobat Reader | CWE-125 | Acrobat Reader | Out-of-bounds Read (CWE-125) |
| CVE-2026-44757 | 4.7 | 5.0 | SAP_SE | SAP Wily Introscope Enterprise Manager | CWE-79 | Cross-Site Scripting (XSS) vulnerability in SAP Wily Introscope Enterprise Ma… |
| CVE-2026-47902 | 6.2 | 5.0 | Adobe | CAI Content Credentials | CWE-400 | CAI Content Credentials | Uncontrolled Resource Consumption (CWE-400) |
| CVE-2026-47903 | 6.2 | 5.0 | Adobe | CAI Content Credentials | CWE-20 | CAI Content Credentials | Improper Input Validation (CWE-20) |
| CVE-2026-47904 | 6.2 | 5.0 | Adobe | CAI Content Credentials | CWE-400 | CAI Content Credentials | Uncontrolled Resource Consumption (CWE-400) |
| CVE-2026-47905 | 6.2 | 5.0 | Adobe | CAI Content Credentials | CWE-400 | CAI Content Credentials | Uncontrolled Resource Consumption (CWE-400) |
| CVE-2026-0412 | 4.3 | 5.0 | NETGEAR | JR6150 | CWE-20 | Insufficient input validation vulnerability in NETGEAR JR6150 Web UI |
| CVE-2026-4058 | 4.3 | 5.0 | wedevs | User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration | CWE-862 | User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membersh… |
| CVE-2026-49762 | 5.1 | 4.9 | elixir-lang | elixir | CWE-400 | Unbounded integer parsing in the Version module enables CPU and memory exhaus… |
| CVE-2026-24064 | 7.8 | 4.8 | Waves Audio Ltd. | Waves Central | CWE-426 | Local Privilege Escalation via Dynamic Library Injection in Waves Central for… |
| CVE-2026-47937 | 7.7 | 4.8 | Adobe | Acrobat Reader | CWE-427 | Acrobat Reader | Uncontrolled Search Path Element (CWE-427) |
| CVE-2026-46539 | 5.9 | 4.7 | nimiq | core-rs-albatross | CWE-345 | nimiq-primitives: BlockInclusionProof interlink issue when hops are empty |
| CVE-2025-67862 | 6.7 | 4.6 | Fortinet | FortiOS | CWE-1244 | An Internal Asset Exposed to Unsafe Debug Access Level or State vulnerability… |
| CVE-2026-8795 | 7.8 | 4.5 | Rapid7 | Velociraptor | CWE-74 | A YAML injection vulnerability exists in the Windows.Collectors.Remapping art… |
| CVE-2026-46517 | 7.8 | 4.5 | InternLM | lmdeploy | CWE-94 | LMDeploy: Hardcoded trust_remote_code=True is an implicit unsafe remote-code … |
| CVE-2026-47909 | 6.3 | 4.5 | Adobe | Dreamweaver Desktop | CWE-20 | Dreamweaver Desktop | Improper Input Validation (CWE-20) |
| CVE-2026-10553 | 4.3 | 4.3 | weaverlancegmailcom | jQuery Hover Footnotes | CWE-352 | jQuery Hover Footnotes <= 1.4 - Cross-Site Request Forgery to Plugin Settings… |
| CVE-2026-34710 | 7.8 | 4.2 | Adobe | Substance3D - Sampler | CWE-787 | Substance3D - Sampler | Out-of-bounds Write (CWE-787) |
| CVE-2026-46432 | 7.8 | 4.0 | InternLM | lmdeploy | CWE-94 | LMDeploy: Arbitrary code execution via hardcoded trust_remote_code=True in lm… |
| CVE-2026-48305 | 7.8 | 4.0 | Adobe | Substance3D - Sampler | CWE-787 | Substance3D - Sampler | Out-of-bounds Write (CWE-787) |
| CVE-2026-48306 | 7.8 | 4.0 | Adobe | Substance3D - Sampler | CWE-787 | Substance3D - Sampler | Out-of-bounds Write (CWE-787) |
| CVE-2026-41846 | 6.1 | 3.9 | Spring | Spring Framework | CWE-79 | Spring Framework Cross-site Scripting via JSP Form Tags |
| CVE-2026-34700 | 7.8 | 3.7 | Adobe | InDesign Desktop | CWE-787 | InDesign Desktop | Out-of-bounds Write (CWE-787) |
| CVE-2026-34706 | 7.8 | 3.7 | Adobe | InCopy | CWE-787 | InCopy | Out-of-bounds Write (CWE-787) |
| CVE-2026-48293 | 7.8 | 3.7 | Adobe | InDesign Desktop | CWE-787 | InDesign Desktop | Out-of-bounds Write (CWE-787) |
| CVE-2026-24181 | 7.3 | 3.8 | NVIDIA | DALI | CWE-129 | NVIDIA DALI contains a vulnerability in a component where an attacker could c… |
| CVE-2026-47900 | 4.6 | 3.7 | logseq | logseq | CWE-79 | Stored XSS via Unsanitized Plugin Metadata in Logseq |
| CVE-2026-47901 | 4.6 | 3.8 | logseq | logseq | CWE-79 | Iframe escape by plugins in Logseq |
| CVE-2026-45782 | 8.9 | 3.7 | cloud-hypervisor | cloud-hypervisor | CWE-416 | Cloud Hypervisor: Use-after-free in virtio-block Async I/O Completion |
| CVE-2026-34709 | 7.8 | 3.7 | Adobe | Substance3D - Sampler | CWE-787 | Substance3D - Sampler | Out-of-bounds Write (CWE-787) |
| CVE-2026-8981 | 3.5 | 3.7 | Unknown | Custom Block Builder | CWE-79 | Lazy Blocks < 4.3.0 - Admin+ Stored XSS via Custom Block Frontend HTML |
| CVE-2026-47899 | 8.7 | 3.6 | logseq | logseq | CWE-749 | Arbitrary File Read, Write, Rename, and Delete in Logseq |
| CVE-2026-46323 | 7.8 | 3.6 | Linux | Linux | CWE-416 | net: gro: don't merge zcopy skbs |
| CVE-2026-47910 | 6.3 | 3.6 | Adobe | Dreamweaver Desktop | CWE-863 | Dreamweaver Desktop | Incorrect Authorization (CWE-863) |
| CVE-2026-41694 | 5.3 | 3.6 | Spring | Spring Security | CWE-347 | SAML Payloads Decrypted Without Valid Signature |
| CVE-2026-41983 | 4.3 | 3.5 | Huawei | HarmonyOS | CWE-399 | Null pointer dereference vulnerability in the browser module. Impact: Success… |
| CVE-2026-46546 | 2.1 | 3.5 | frappe | lms | CWE-79 | Frappe LMS: HTML injection in user-controlled metadata |
| CVE-2026-0420 | 4.6 | 3.5 | NETGEAR | RAX120v1 | CWE-325 | Missing TLS certificate validation in NETGEAR's ReadyCloud client app |
| CVE-2026-41844 | 6.1 | 3.4 | Spring | Spring Framework | CWE-601 | Spring Framework Open Redirect in Spring MVC and WebFlux |
| CVE-2026-41982 | 6.4 | 3.3 | Huawei | HarmonyOS | CWE-416 | Race condition vulnerability in the IPC module. Impact: Successful exploitati… |
| CVE-2026-46326 | 8.4 | 3.2 | Linux | Linux | — | iio: pressure: mprls0025pa: fix spi_transfer struct initialisation |
| CVE-2026-22926 | 7.8 | 3.2 | Omnissa | Omnissa Workspace ONE® Assist for macOS | CWE-22 | Omnissa Workspace ONE® Assist for macOS contains a Local Privilege Escalation… |
| CVE-2026-41714 | 4.0 | 3.2 | Spring | Spring AMQP | CWE-295 | In Spring AMQP the RabbitConnectionFactoryBean.setUri("amqps://...") bypasses… |
| CVE-2026-46317 | 8.8 | 3.1 | Linux | Linux | — | KVM: arm64: Reassign nested_mmus array behind mmu_lock |
| CVE-2026-34703 | 5.5 | 3.1 | Adobe | InDesign Desktop | CWE-476 | InDesign Desktop | NULL Pointer Dereference (CWE-476) |
| CVE-2026-34704 | 5.5 | 3.1 | Adobe | InDesign Desktop | CWE-476 | InDesign Desktop | NULL Pointer Dereference (CWE-476) |
| CVE-2026-46321 | 7.1 | 3.0 | Linux | Linux | — | tun: free page on short-frame rejection in tun_xdp_one() |
| CVE-2026-46322 | 7.1 | 3.0 | Linux | Linux | — | tun: free page on build_skb failure in tun_xdp_one() |
| CVE-2026-8909 | 4.3 | 2.9 | rahulbhangale | WpMobi | CWE-352 | WpMobi <= 0.0.3 - Cross-Site Request Forgery via save_general_settings Action |
| CVE-2026-8940 | 4.3 | 2.9 | jasonpitts | WP Meta Sort Posts | CWE-352 | WP Meta Sort Posts <= 0.9 - Cross-Site Request Forgery to Plugin Settings Update |
| CVE-2025-54509 | 4.0 | 2.8 | AMD | AMD EPYC™ 9004 Series Processors | CWE-1262 | Improper access control for register interface in the Input-Output Memory Man… |
| CVE-2026-46319 | 7.8 | 2.6 | Linux | Linux | CWE-416 | net/sched: act_ct: Only release RCU read lock after ct_ft |
| CVE-2026-8902 | 4.3 | 2.5 | tierrainnovation | AJAX Report Comments | CWE-352 | AJAX Report Comments <= 2.0.4 - Cross-Site Request Forgery to Settings Update |
| CVE-2026-8904 | 4.3 | 2.5 | yuluma | FastPicker, an order picker and order management system (oms) for WooCommerce on steroids | CWE-352 | FastPicker, an order picker and order management system (oms) for WooCommerce… |
| CVE-2026-11623 | 1.1 | 2.5 | n/a | tmux | CWE-119 | tmux image.c image_free use after free |
| CVE-2023-29146 | 8.2 | 2.5 | n/a | n/a | CWE-190 | The utility functions used by Malwarebytes EDR 1.0.11 on Linux for calculatin… |
| CVE-2026-41854 | 6.5 | 2.5 | Spring | Spring Framework | CWE-918 | Spring Framework Server-Side Request Forgery via UriComponentsBuilder |
| CVE-2026-52906 | 7.7 | 2.2 | Linux | Linux | — | 9p: fix access mode flags being ORed instead of replaced |
| CVE-2026-46749 | 4.9 | 2.3 | Siemens | SINEC INS | CWE-760 | A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Upd… |
| CVE-2026-52902 | 4.7 | 2.3 | Red Hat | Red Hat Ansible Automation Platform 2 | CWE-22 | Awxkit: path traversal via yaml !include directive |
| CVE-2026-46327 | 7.8 | 2.1 | Linux | Linux | — | dm: fix unlocked test for dm_suspended_md |
| CVE-2026-8910 | 6.1 | 2.2 | rahulbhangale | WP Emoticon Rating | CWE-352 | WP Emoticon Rating <= 1.0.1 - Cross-Site Request Forgery to Reflected Cross-S… |
| CVE-2026-46324 | 7.8 | 2.0 | Linux | Linux | — | netfilter: nf_tables: use list_del_rcu for netlink hooks |
| CVE-2026-9735 | 6.8 | 2.1 | MongoDB | MongoDB Server | CWE-532 | Keyfile contents are in MongoDB Server logs |
| CVE-2026-8907 | 6.1 | 2.1 | rahulbhangale | WP-Ultimate-Map | CWE-352 | WP-Ultimate-Map <= 1.1 - Cross-Site Request Forgery to Stored Cross-Site Scri… |
| CVE-2023-43686 | 6.2 | 2.0 | n/a | n/a | CWE-755 | An issue was discovered in Malwarebytes 4.x and 5.x (and Nebula 2020-10-21 an… |
| CVE-2026-47838 | 8.1 | 1.9 | Spring | Spring Security | CWE-287 | Unauthorized User Impersonation when Using X.509 Client Certificates |
| CVE-2026-46328 | 7.3 | 1.7 | Linux | Linux | — | apparmor: fix rlimit for posix cpu timers |
| CVE-2026-46315 | 5.5 | 1.7 | Linux | Linux | — | io_uring/waitid: clear waitid info before copying it to userspace |
| CVE-2026-46329 | 5.5 | 1.7 | Linux | Linux | — | erofs: handle end of filesystem properly for file-backed mounts |
| CVE-2026-52904 | 5.5 | 1.7 | Linux | Linux | CWE-401 | drm/nouveau: fix nvkm_device leak on aperture removal failure |
| CVE-2026-46330 | 7.8 | 1.6 | Linux | Linux | CWE-416 | Revert "net/smc: Introduce TCP ULP support" |
| CVE-2026-52907 | 7.8 | 1.6 | Linux | Linux | CWE-193 | media: rockchip: rkcif: fix off by one bugs |
| CVE-2026-52905 | 5.5 | 1.6 | Linux | Linux | CWE-1284 | mm/damon/core: disallow non-power of two min_region_sz on damon_start() |
| CVE-2026-8863 | 7.8 | 1.5 | Oracle Corporation | OracleLinux(7.2) shim | — | CVE-2026-8863 |
| CVE-2026-41986 | 2.4 | 1.5 | Huawei | HarmonyOS | CWE-606 | Logic bypass vulnerability in the file system. Impact: Successful exploitatio… |
| CVE-2026-9751 | 6.8 | 1.4 | MongoDB | MongoDB Server | CWE-532 | Sensitive data could be written to mongod.log |
| CVE-2026-44755 | 4.3 | 1.4 | SAP_SE | SAP Business Objects Business Intelligence Platform | CWE-346 | Email Spoofing vulnerability in SAP Business Objects Business Intelligence Pl… |
| CVE-2026-6899 | 5.6 | 1.4 | Systerel | S2OPC | CWE-299 | Improper Check for Certificate Revocation in S2OPC |
| CVE-2026-39170 | 6.3 | 1.3 | n/a | n/a | CWE-352 | SemCms 5.0 is vulnerable to Cross Site Request Forgery (CSRF) via crafted POS… |
| CVE-2026-9741 | 7.1 | 1.1 | MongoDB | MongoDB Server | CWE-319 | Client side encryption fails to encrypt values in a $vectorSearch |
| CVE-2026-0466 | 6.8 | 1.0 | AMD | AMD µProf | CWE-497 | Improper access control in AMD uProf may allow a local attacker with user pri… |
| CVE-2026-46318 | 5.5 | 1.0 | Linux | Linux | — | Revert "mm/hugetlbfs: update hugetlbfs to use mmap_prepare" |
| CVE-2026-28237 | 6.8 | 0.9 | AMD | AMD µProf | CWE-770 | Unrestricted resource allocation in AMD uProf may be exploitable to consume e… |
| CVE-2026-44275 | 6.3 | 0.9 | Dell | Dell/Alienware Purchased Apps | CWE-59 | Dell/Alienware Purchased Apps, versions prior to 1.1.32.0, contain an Imprope… |
| CVE-2026-28262 | 6.0 | 0.7 | Dell | iDRAC Tools | CWE-59 | Dell iDRAC Tools, versions prior to 11.4.1.0, contains an Improper Link Resol… |
| CVE-2026-41980 | 5.5 | 0.4 | Huawei | HarmonyOS | CWE-200 | Permission control vulnerability in the file preview module. Impact: Successf… |
| CVE-2026-2638 | 7.3 | 0.4 | X-VPN | X-VPN macOS website | CWE-367 | X-VPN macOS website versions - Local Privilege Escalation |
| CVE-2026-41116 | 6.3 | 0.3 | Dell | Inventory Collector Client | CWE-1386 | Dell Inventory Collector Client, versions prior to 13.8.0, contain an Imprope… |
| CVE-2026-49958 | 4.3 | 0.3 | nesquena | hermes-webui | CWE-367 | Hermes WebUI < 0.51.303 TOCTOU Race Condition via git_discard |
| CVE-2026-41976 | 6.6 | 0.2 | Huawei | HarmonyOS | CWE-275 | Permission control vulnerability in the audio framework. Impact: Successful e… |
| CVE-2026-41973 | 5.9 | 0.2 | Huawei | HarmonyOS | CWE-840 | Permission control vulnerability in calls. Impact: Successful exploitation of… |
| CVE-2026-41984 | 5.2 | 0.2 | Huawei | HarmonyOS | CWE-284 | UAF vulnerability in the package management module. Impact: Successful exploi… |
| CVE-2026-41979 | 5.5 | 0.1 | Huawei | HarmonyOS | CWE-701 | Permission control vulnerability in the print module. Impact: Successful expl… |
| CVE-2026-41977 | 5.0 | 0.1 | Huawei | HarmonyOS | CWE-190 | DoS vulnerability in the log service. Impact: Successful exploitation of this… |
| CVE-2026-41978 | 4.4 | 0.1 | Huawei | HarmonyOS | CWE-275 | Permission control vulnerability in the clone module. Impact: Successful expl… |
| CVE-2026-41974 | 3.6 | 0.1 | Huawei | HarmonyOS | CWE-264 | Permission control vulnerability in service notifications. Impact: Successful… |
| CVE-2026-41985 | 5.1 | 0.1 | Huawei | HarmonyOS | CWE-284 | UAF vulnerability in the package management module. Impact: Successful exploi… |
| CVE-2026-41981 | 5.3 | 0.1 | Huawei | HarmonyOS | CWE-122 | Out-of-bounds write vulnerability in the IPC module. Impact: Successful explo… |
| CVE-2026-41975 | 6.3 | 0.0 | Huawei | HarmonyOS | CWE-701 | Permission management vulnerability in the network management module. Impact:… |
| CVE-2026-24349 | 8.2 | 0.0 | Siemens | SIMATIC WinCC Unified PC Runtime V16 | CWE-313 | A vulnerability has been identified in SIMATIC WinCC Unified PC Runtime V16 (… |